Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
8,460 exploits
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALunder attack16 Jan 2018
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware16 Jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
client-side
CVE-2018-0802HIGHunder attack12 Jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware12 Jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
client-side
CVE-2018-0802HIGHunder attack11 Jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware11 Jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
client-side
CVE-2018-0802HIGHunder attack11 Jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
VulnCheck XDB
infoleak
CVE-2016-2388MEDIUMunder attack10 Jan 2018
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RISK
open
VulnCheck XDB
initial-access
CVE-2016-2386CRITICALunder attack10 Jan 2018
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
client-side
CVE-2017-8570HIGHunder attack09 Jan 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
VulnCheck XDB
initial-access
CVE-2017-11317CRITICALunder attack09 Jan 2018
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISK
open
VulnCheck XDB
local
CVE-2012-4681CRITICALunder attackransomware05 Jan 2018
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware05 Jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware03 Jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-3881CRITICALunder attack02 Jan 2018
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open
VulnCheck XDB
local
CVE-2017-1315629 Dec 2017
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware28 Dec 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware28 Dec 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-17562HIGHunder attack27 Dec 2017
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12615HIGHunder attackransomware26 Dec 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware25 Dec 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware23 Dec 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALunder attackransomware22 Dec 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-15944CRITICALunder attack19 Dec 2017
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9805HIGHunder attack04 Dec 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9805HIGHunder attack28 Nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALunder attackransomware28 Nov 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware27 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9805HIGHunder attack24 Nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack23 Nov 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
previouspage 273 / 282next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.